Improper Authorization in AirPods firmware and Beats firmware - CVE-2024-27867

 

Improper Authorization in AirPods firmware and Beats firmware - CVE-2024-27867

Published: June 27, 2024


Vulnerability identifier: #VU93406
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27867
CWE-ID: CWE-285
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker to perform spoofing attack.

The vulnerability exists due to the way the headphones are seeking a connection request to one of your previously paired devices. An attacker with physical proximity to the device can spoof the intended source device and gain access to your headphones.


Affected software

AirPods firmware
Beats firmware

How to mitigate CVE-2024-27867

Install updates from vendor's website.

AirPods firmware - addressed in versions 6A326, 6F8
Beats firmware - update to 6F8

External References

Related Security Bulletins